Web, Mobile, API, Cloud & Infrastructure | U.S.-Based
At TechCompass, penetration testing is about more than producing a list of vulnerabilities.
Our testers simulate realistic attack paths, validate whether weaknesses can actually be exploited, determine potential business impact, and give clients clear guidance on what needs to change.
We work with organizations at different stages of security maturity, from growing technology companies to established businesses with complex environments. Engagements vary, which means our testers need technical depth, curiosity, sound judgment, and the ability to communicate clearly with clients.
This is an evergreen opportunity. We’re always interested in connecting with experienced U.S.-based penetration testers as our team and client needs grow.
How this works: These are 1099 subcontractor engagements, not W2 employment. Work is project-based and varies in scope and duration by engagement. Remote, U.S.-based.
Depending on your specialization and the engagement, you may:
Strong candidates will typically bring:
We are not expecting every penetration tester to be an expert across every technology.
We are interested in candidates with strong capabilities in one or more of the following:
Experience with additional areas such as source-code review, wireless testing, social engineering, red teaming, container security, Kubernetes, or emerging technologies is also valuable.
Depending on your specialization, your experience may include tools and technologies such as Burp Suite, Nmap, Metasploit, BloodHound, Impacket, cloud-native security tooling, scripting languages, mobile testing frameworks, or other offensive-security platforms.
We don’t hire based on a tool checklist. We’re more interested in whether you understand why a vulnerability exists, how to validate it safely, what an attacker could realistically do with it, and how the client should address it.
Certifications such as OSCP, OSWE, OSEP, GPEN, GWAPT, PNPT, or similar credentials are valued but are not a substitute for practical experience.
The best penetration testers for our team aren’t just technically capable.
They can move from:
“I found a vulnerability.”
to:
“Here’s how an attacker could use it, what it puts at risk, how serious it is in this environment, and what you should do next.”
That ability to connect technical findings to real-world risk is central to how TechCompass works with clients.
TechCompass is a boutique cybersecurity firm focused on expert-led, practical security work.
Our broader team works across assessments, cloud and product security, security program development, compliance, security engineering, and strategic advisory, giving penetration testers the opportunity to see how offensive-security findings fit into a client’s larger security program.
You’ll work across varied environments and meaningful security challenges alongside experienced practitioners who value technical depth, clear communication, and work clients can actually use.
Whether your specialty is web applications, mobile, APIs, cloud, infrastructure, or a combination, we’d like to hear from you.
Tell us where you’re strongest, the types of environments you’ve tested, and the kind of offensive-security work you want to take on next.
Submit your application to be considered for current and future opportunities with TechCompass.
.webp)